Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-mj5w-w588-j6xg: Use of Hard-coded Credentials in AgileConfig.Client

Hardcoded JWT Secret in AgileConfig <1.6.8 Server allows remote attackers to use the generated JWT token to gain administrator access.

ghsa
#git#hard_coded_credentials

Use of Hard-coded Credentials in AgileConfig.Client

Critical severity GitHub Reviewed Published Aug 19, 2022 • Updated Aug 30, 2022

Related news

CVE-2022-35540: security vulnerability (存在安全漏洞) · Issue #91 · dotnetcore/AgileConfig

Hardcoded JWT Secret in AgileConfig <1.6.8 Server allows remote attackers to use the generated JWT token to gain administrator access.